brex

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose matches finance-platform operations, and the installer is an official npm package from the same ecosystem, so this is not overt malware. However, all Brex access and authentication are mediated through Membrane rather than direct Brex APIs, expanding trust to a third-party gateway that stores and refreshes credentials and can access sensitive financial data; combined with unpinned CLI execution, this makes the skill medium risk.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Sep 15, 2026, 08:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbrex%2F@ba7cb727edaf329d7f34151c0306619113d640ad40734156711c8ff4d6204600
Security Audit — socket — brex